Skip to main content

Vendor archive

openjsf CVEs

Beta · best-effort

19 CVEs tagged to vendor openjsf1 Critical, 9 High, 7 Medium, 2 Low, 0 Unrated.

CVE-2026-12590

Published Jul 9, 2026

Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or…

CVSS 3.7 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-13676

Published Jun 29, 2026

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on th…

CVSS 7.5 · High
evidence mentions
19
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-10796

Published Jun 4, 2026

nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands such as `nvm install` read the…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-25244

Published May 18, 2026

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulner…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-6322

Published May 5, 2026

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined a…

CVSS 7.5 · High
evidence mentions
35
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-6321

Published May 4, 2026

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like…

CVSS 7.5 · High
evidence mentions
22
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2025-50537

Published Jan 26, 2026

Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the Rule…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57349

Published Sep 24, 2025

The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10491

Published Oct 29, 2024

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45590

Published Sep 10, 2024

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43800

Published Sep 10, 2024

serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-st…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43796

Published Sep 10, 2024

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. Thi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29900

Published Mar 29, 2024

Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29041

Published Mar 25, 2024

Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerabil…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26136

Published Feb 20, 2024

kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an account access token in the `config.json` file. Malicious actors…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6393

Published Aug 9, 2017

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8856

Published Jan 23, 2017

Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary web script or HTML via a crafted file or d…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1